Developer docs
API playgroundTry for free, no card

Search company profiles

Sherlock

Full company profile

uuid0000pfz

Namestring
Sherlock
Legal namestring
Sherlock Protocol
Websiteurl
sherlock.xyz
Company typeenum
Private
Founded yearint
2021
Descriptiontext

Sherlock (legal entity Sherlock Protocol) is a Web3 security platform headquartered in Miami, founded in 2021 by Jack Sanford. The company provides lifecycle security for smart contract-based protocols, spanning the development stage through post-launch operation. Its core offerings are Sherlock AI, Collaborative Audits, Audit Contests, Bug Bounties, and Sherlock Shield (exploit coverage), with a Blackthorn elite audit tier reserved for high-stakes infrastructure reviews. The platform addresses a clearly defined pain point: traditional point-in-time audits leave protocols exposed to vulnerabilities introduced after the audit window, and Sherlock's model layers continuous discovery (bounties), AI-assisted pre-commit analysis, and optional financial coverage to close that gap.

Under the hood, Sherlock operates a community-sourced model with 11,000+ ranked security researchers whose performance data feeds team staffing decisions for each engagement. The Sherlock AI product combines a proprietary two-stage run architecture (discovery and verification) with a planner-and-specialists multi-agent system (Economic Logic, Math and Crypto, State Transition, Code Correctness, MEV Detection, External Integration, Access Control) and beta support for Solana Rust beyond EVM-only analysis. Sherlock Shield adds financial protection up to $500K for live protocols after a covered issue is exploited, layered on top of ongoing bug bounty programs.

Sherlock monetizes through professional services fees on collaborative audits and audit contests, managed-services and platform fees on bug bounty programs (including a stake-to-submit model at $250 USDC per report), insurance premiums on Sherlock Shield, and affiliate referral fees ($1,000 per qualified audit/AI referral, $500 per bounty referral). Customers span DeFi (Aave, Morpho, Sky, Maple, Perennial, Flying Tulip, Usual), L1/L2 infrastructure (Ethereum Foundation, Aptos, Mantle, Babylon, Cosmos/Interchain Labs), cross-chain (LayerZero, MegaETH), and RWA infrastructure (Centrifuge). The platform reports supporting protocols responsible for more than $250B in active TVL, completing over 1,000 private audits and 370+ audit contests, and surfacing 2,000+ critical issues cumulatively. Sherlock has raised $4M in seed funding (September 2022, led by Archetype with CoinFund, Lattice Capital, and The Spartan Group), operates with 1-10 employees, and has not disclosed additional funding or revenue.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
101–250
akta.pro rankint
HeadquartersMiami, United States
HQ citystring
Miami
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Keyword5 values
smart contract auditing, web3 security services, bug bounty programs, blockchain audit platform, smart contract review
Industry9 codes
1Bug Bounty, Vulnerability Disclosure & Security Services
CodeFSAPAJALPrimaryYes
2On-Chain Monitoring, Threat Detection & Incident Response
CodeFSAPAJABPrimaryNo
3Anti-Cheat, Security & Fraud Prevention for Web3 Games (bot detection, exploit prevention)
CodeFSAPAGALPrimaryNo
4Social Engineering / Funds Transfer Fraud Coverage
CodeFSAJAOAIPrimaryNo
5Cyber Risk Management Services (Pre-Breach Services bundled with Insurance)
CodeFSAJAOAOPrimaryNo
6Secure Model Deployment & Runtime Protection (sandboxing, isolation)
CodeHDAAAKAHPrimaryNo
7Secrets Management (Passwords, API Keys, Tokens)
CodeHDADAFADPrimaryNo
8Insider Threat Program Design & Risk Assessments
CodeBPAKADAMPrimaryNo
9Cyber Extortion / Ransomware Coverage
CodeFSAJAOAHPrimaryNo
NAICS code2 codes
  • Security Systems Services (except Locksmiths)561621
  • Security Systems Services56162
SIC code2 codes
  • Security & Commodity Brokers, Dealers, Exchanges & Services6200
  • Services-Detective, Guard & Armored Car Services7381
Product category
Web3 Smart Contract Security Services
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model5 records
1Collaborative Audits
TypeProfessional Services
Description

Private, senior-led audit engagements where Sherlock assembles a curated team from its ranked researcher network. Pricing varies by scope complexity, codebase size, and team composition. Teams like Blackthorn tier command premium pricing for high-stakes infrastructure reviews.

sherlock.xyz
2Audit Contests
TypeProfessional Services
Description

Time-limited competitive review competitions where protocols open their code to independent researchers. Sherlock takes a fee from the prize pool structure and engagement scoping. Prize pools can range from $100K to $2M+ (e.g., Ethereum Foundation Fusaka contest had $2M max prize pool).

sherlock.xyz
3Bug Bounties
TypeManaged Services
Description

Ongoing vulnerability discovery programs for deployed protocols. Sherlock provides platform infrastructure, expert triage, and coverage options. Programs include stake-to-submit model ($250 USDC per report) with Sherlock providing adjudication and coverage up to $500K. Revenue from platform fees and coverage premiums.

sherlock.xyz
4Referral Program
TypeAffiliate Referral
Description

Sherlock pays referral fees to ecosystem participants who introduce protocol teams: $1,000 per qualified audit referral, $1,000 per Sherlock AI referral, $500 per bug bounty referral. Sherlock runs sales and delivery; referrers are compensated when customers purchase.

sherlock.xyz
5Sherlock Shield Coverage
TypeOthers
Description

Optional exploit coverage product for qualifying audited codebases. Provides financial protection during live operation if covered issues appear. Includes post-exploit coverage up to $500K for bug bounty programs.

sherlock.xyz
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Pricing details4 tiers
1Stake-to-submit bug bounty model with expert triage
ModelOtherBilling cadencePay-as-you-go
Notes

Researchers stake $250 USDC per report, refunded if the issue is valid. Sherlock provides expert triage achieving 52% hit rate. Post-exploit coverage up to $500K included with all programs.

sherlock.xyz
2Referral fees for qualified introductions
ModelOtherBilling cadencePay-as-you-go
Notes

$1,000 for qualified audit referrals; $1,000 for qualified Sherlock AI referrals; $500 for qualified bug bounty referrals. Referrals eligible for 180 days from submission.

sherlock.xyz
3Ethereum Foundation Fusaka audit contest prize pool structure
ModelOutcome Based/ PerformanceBilling cadenceOne-time
Notes

Maximum prize pool: $2,000,000. Tiered unlocking: Low=$50K, Medium=$200K, High=$500K, Critical=$2,000K. Early Report Multipliers: Week 1=2x, Week 2=1.5x on valid reports.

sherlock.xyz
4Flying Tulip ftPUT audit contest reward pool
ModelOutcome Based/ PerformanceBilling cadenceOne-time
Notes

$100,000 USDC in rewards for the Sherlock audit contest reviewing ftPUT contracts.

sherlock.xyz
GTM typeB2B
B2B
Offering typeServices
Services
Brand1 record
1Blackthorn
Description

Sherlock's elite tier of auditors, reserved for high-stakes infrastructure and complex scopes, staffed by top-performing Web3 security researchers from Sherlock's network.

sherlock.xyz
Core offering1 text field

Sherlock provides lifecycle security services for Web3 protocols, combining AI-powered smart contract analysis (Sherlock AI), senior-led private audits (Collaborative Audits, including the Blackthorn elite tier), large-scale adversarial contests (Audit Contests), ongoing post-launch vulnerability discovery (Bug Bounties), and financial exploit coverage (Sherlock Shield). Engagements are staffed from a network of 11,000+ ranked security researchers matched to each protocol's architecture.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 5 values shown
  • Supports protocols with $250B+ in active TVL
+4 more records
Product overview1 text field

Sherlock is a Web3 lifecycle security platform offering a unified, integrated system of security products spanning development, pre-launch auditing, and post-launch protection. The platform operates as a platform-plus-modules architecture with five core offerings: Sherlock AI (AI-powered smart contract analysis during development), Collaborative Audits (senior-led private reviews), Audit Contests (large-scale adversarial pre-launch reviews), Bug Bounties (ongoing post-launch vulnerability discovery), and Sherlock Shield (financial exploit coverage for live protocols). Blackthorn serves as an elite audit tier within the collaborative audit model, staffed by invite-only top researchers for the highest-stakes engagements. Supporting resources include Docs, Blog, Podcast, Case Studies, a Referral Program, a Lifecycle eBook, Leaderboards, and the Sherlock App. The platform is trusted by leading protocols including Aave, Ethereum Foundation, Morpho, Centrifuge, Perennial, MegaETH, and LayerZero.

Product and service6 records
1Sherlock AI
CategoryAI Security Software
Description

AI-powered smart contract analysis tool that delivers auditor-level analysis during development for Web3 protocol teams, using a two-stage run system (discovery plus verification), domain-specific specialist workflows, and GitHub integration to catch vulnerabilities early.

2Collaborative Audits
CategoryProfessional Security Services
Description

Private, senior-led code review engagements staffed from Sherlock's ranked researcher network. Sherlock assembles a curated expert team to review a protocol's codebase in a dedicated engagement with close developer collaboration, prior to mainnet or major releases.

3Audit Contests
CategoryProfessional Security Services
Description

Time-limited competitive security reviews that open a protocol's codebase to hundreds of independent researchers competing to surface the most impactful issues, applying large-scale adversarial pressure before protocol launch.

4Bug Bounties
CategoryManaged Security Services
Description

Ongoing post-launch vulnerability discovery programs using a stake-to-submit model ($250 USDC per report, refunded if valid), with expert triage by Sherlock's lead auditors and a 52% hit rate on impactful submissions. Includes post-exploit coverage up to $500K for qualifying programs.

5Sherlock Shield
CategorySecurity Coverage / Insurance
Description

Financial exploit coverage product for live protocols that have been audited, adding a protection layer during active operation if a covered issue is exploited. Includes post-exploit coverage up to $500K for qualifying bug bounty programs.

6Blackthorn
CategoryPremium Professional Security Services
Description

Sherlock's elite audit tier, invite-only for top-performing researchers in the network and reserved for high-stakes infrastructure and complex scopes. Blackthorn researchers lead engagements on critical protocols such as Aave V4, Morpho Vaults V2, and the Ethereum Foundation Fusaka upgrade.

Scale indicator9 records

Each record includes

Type, Value, Description, Source

Partnership2 partners
Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-03-01
Description

Usual partnered with Sherlock to launch the largest bug bounty in tech history at $16 million for a single critical vulnerability, eclipsing previous records by Uniswap ($15.5M) and LayerZero ($15M). The program covers Usual's full smart contract suite including stablecoin infrastructure, yield distribution, and governance contracts. Sherlock provides its stake-to-submit model with expert triage and post-exploit coverage.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2025-09-15
Description

Ethereum Foundation's Protocol Security Team partnered with Sherlock for a large-scale audit contest as the final stress test before Fusaka's mainnet launch. The 28-day contest drew 510+ researchers with a $2M max prize pool. Sherlock mobilized its researcher network to surface 4 high-severity findings before the December 2025 Fusaka upgrade. The Foundation continues with an ongoing $250K bug bounty.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Code4rena operates audit contests and bug bounties for Web3 protocols, directly competing with Sherlock's contest and bounty offerings. Both platforms use crowdsourced reviewer models to surface vulnerabilities before protocol launches.

TypeDirect peer
Description

Cantina is a newer Web3 security platform offering audits, contests, and bug bounties with a curated researcher network. It competes directly with Sherlock across the audit contest and bug bounty product categories.

TypeBroad incumbent
Description

OpenZeppelin is a leading smart contract security and development firm offering audits, security libraries, and developer tools. It is a broader incumbent with overlapping audit services but a different model (fixed roster of senior auditors rather than crowdsourced).

TypeBroad incumbent
Description

Trail of Bits is a well-established cybersecurity firm with significant Web3 smart contract audit practice. It competes for high-stakes audit engagements (e.g., Aave, Morpho) and offers broader security services beyond Web3.

TypeDirect peer
Description

Spearbit provides curated smart contract audit services led by senior security researchers. It directly competes with Sherlock's Collaborative Audits and Blackthorn tier engagements.

TypeBroad incumbent
Description

Consensys Diligence is the audit arm of Consensys, one of the largest Web3 infrastructure companies. It offers smart contract audits and competes for major protocol engagements as a broader incumbent.

TypeDirect peer
Description

Immunefi is the largest bug bounty platform specifically for Web3, directly competing with Sherlock's Bug Bounty product. Both platforms host ongoing vulnerability disclosure programs with major protocols.

TypeDirect peer
Description

Zellic is a smart contract audit firm specializing in cryptographic and high-stakes protocol audits. It competes for premium audit engagements similar to Sherlock's Blackthorn tier.

TypeEmerging player
Description

Certora provides formal verification and security analysis tools for smart contracts. It is an emerging player using a different technical approach (formal verification) that overlaps with Sherlock AI's pre-launch analysis capabilities.

TypeDirect peer
Description

Hacken is a Web3 cybersecurity auditor offering smart contract audits, bug bounties, and security scoring services. It competes with Sherlock across multiple security service categories.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers15 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment1 record

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile2 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

Integration1 record

Each record includes

Title, Type, Description, Source

AI capability5 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature9 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles2 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds1 record

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors5 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Sherlock

Web3 Smart Contract Security Servicessherlock.xyz

What Sherlock does

Sherlock (legal entity Sherlock Protocol) is a Web3 security platform headquartered in Miami, founded in 2021 by Jack Sanford. The company provides lifecycle security for smart contract-based protocols, spanning the development stage through post-launch operation. Its core offerings are Sherlock AI, Collaborative Audits, Audit Contests, Bug Bounties, and Sherlock Shield (exploit coverage), with a Blackthorn elite audit tier reserved for high-stakes infrastructure reviews. The platform addresses a clearly defined pain point: traditional point-in-time audits leave protocols exposed to vulnerabilities introduced after the audit window, and Sherlock's model layers continuous discovery (bounties), AI-assisted pre-commit analysis, and optional financial coverage to close that gap.

Under the hood, Sherlock operates a community-sourced model with 11,000+ ranked security researchers whose performance data feeds team staffing decisions for each engagement. The Sherlock AI product combines a proprietary two-stage run architecture (discovery and verification) with a planner-and-specialists multi-agent system (Economic Logic, Math and Crypto, State Transition, Code Correctness, MEV Detection, External Integration, Access Control) and beta support for Solana Rust beyond EVM-only analysis. Sherlock Shield adds financial protection up to $500K for live protocols after a covered issue is exploited, layered on top of ongoing bug bounty programs.

Sherlock monetizes through professional services fees on collaborative audits and audit contests, managed-services and platform fees on bug bounty programs (including a stake-to-submit model at $250 USDC per report), insurance premiums on Sherlock Shield, and affiliate referral fees ($1,000 per qualified audit/AI referral, $500 per bounty referral). Customers span DeFi (Aave, Morpho, Sky, Maple, Perennial, Flying Tulip, Usual), L1/L2 infrastructure (Ethereum Foundation, Aptos, Mantle, Babylon, Cosmos/Interchain Labs), cross-chain (LayerZero, MegaETH), and RWA infrastructure (Centrifuge). The platform reports supporting protocols responsible for more than $250B in active TVL, completing over 1,000 private audits and 370+ audit contests, and surfacing 2,000+ critical issues cumulatively. Sherlock has raised $4M in seed funding (September 2022, led by Archetype with CoinFund, Lattice Capital, and The Spartan Group), operates with 1-10 employees, and has not disclosed additional funding or revenue.

Sherlock firmographics

Firmographics
Name
Sherlock
Legal name
Sherlock Protocol
Website
https://sherlock.xyz
Company type
Private
Founded year
2021
Operating status
Operating
Headcount range
101–250 employees
Ownership category
akta.pro rank

Sherlock industry classification

Industry
Product category
Web3 Smart Contract Security Services
NAICS
Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
SIC
Security & Commodity Brokers, Dealers, Exchanges & Services (6200), Services-Detective, Guard & Armored Car Services (7381)
akta.pro primary industry
Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
akta.pro secondary industries
On-Chain Monitoring, Threat Detection & Incident Response (FSAPAJAB), Anti-Cheat, Security & Fraud Prevention for Web3 Games (bot detection, exploit prevention) (FSAPAGAL), Social Engineering / Funds Transfer Fraud Coverage (FSAJAOAI), Cyber Risk Management Services (Pre-Breach Services bundled with Insurance) (FSAJAOAO), Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH), Secrets Management (Passwords, API Keys, Tokens) (HDADAFAD), Insider Threat Program Design & Risk Assessments (BPAKADAM), Cyber Extortion / Ransomware Coverage (FSAJAOAH)

Keywords

  • Smart contract auditing
  • Web3 security services
  • Bug bounty programs
  • Blockchain audit platform
  • Smart contract review

Where Sherlock is headquartered

Location

Headquarters

HQ city
Miami
HQ country
United States
HQ region
North America

Markets served

Sherlock business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Technology or R&D, Marketing or Sales, Operations, Others

Revenue model

  1. Collaborative Audits: Private, senior-led audit engagements where Sherlock assembles a curated team from its ranked researcher network. Pricing varies by scope complexity, codebase size, and team composition. Teams like Blackthorn tier command premium pricing for high-stakes infrastructure reviews.
  2. Audit Contests: Time-limited competitive review competitions where protocols open their code to independent researchers. Sherlock takes a fee from the prize pool structure and engagement scoping. Prize pools can range from $100K to $2M+ (e.g., Ethereum Foundation Fusaka contest had $2M max prize pool).
  3. Bug Bounties: Ongoing vulnerability discovery programs for deployed protocols. Sherlock provides platform infrastructure, expert triage, and coverage options. Programs include stake-to-submit model ($250 USDC per report) with Sherlock providing adjudication and coverage up to $500K. Revenue from platform fees and coverage premiums.
  4. Referral Program: Sherlock pays referral fees to ecosystem participants who introduce protocol teams: $1,000 per qualified audit referral, $1,000 per Sherlock AI referral, $500 per bug bounty referral. Sherlock runs sales and delivery; referrers are compensated when customers purchase.
  5. Sherlock Shield Coverage: Optional exploit coverage product for qualifying audited codebases. Provides financial protection during live operation if covered issues appear. Includes post-exploit coverage up to $500K for bug bounty programs.

Pricing tiers

ModelBillingPrice
OtherPay-as-you-goStake-to-submit bug bounty model with expert triage
OtherPay-as-you-goReferral fees for qualified introductions
Outcome Based/ PerformanceOne-timeEthereum Foundation Fusaka audit contest prize pool structure
Outcome Based/ PerformanceOne-timeFlying Tulip ftPUT audit contest reward pool

Go-to-market motion3 records

Distribution channels4 records

Marketing channels7 records

Sherlock product offering

Product offering

Core offering

Sherlock provides lifecycle security services for Web3 protocols, combining AI-powered smart contract analysis (Sherlock AI), senior-led private audits (Collaborative Audits, including the Blackthorn elite tier), large-scale adversarial contests (Audit Contests), ongoing post-launch vulnerability discovery (Bug Bounties), and financial exploit coverage (Sherlock Shield). Engagements are staffed from a network of 11,000+ ranked security researchers matched to each protocol's architecture.

Product overview

Sherlock is a Web3 lifecycle security platform offering a unified, integrated system of security products spanning development, pre-launch auditing, and post-launch protection. The platform operates as a platform-plus-modules architecture with five core offerings: Sherlock AI (AI-powered smart contract analysis during development), Collaborative Audits (senior-led private reviews), Audit Contests (large-scale adversarial pre-launch reviews), Bug Bounties (ongoing post-launch vulnerability discovery), and Sherlock Shield (financial exploit coverage for live protocols). Blackthorn serves as an elite audit tier within the collaborative audit model, staffed by invite-only top researchers for the highest-stakes engagements. Supporting resources include Docs, Blog, Podcast, Case Studies, a Referral Program, a Lifecycle eBook, Leaderboards, and the Sherlock App. The platform is trusted by leading protocols including Aave, Ethereum Foundation, Morpho, Centrifuge, Perennial, MegaETH, and LayerZero.

Differentiator

Problem solved

Functional benefit

Brands

  • Blackthorn: Sherlock's elite tier of auditors, reserved for high-stakes infrastructure and complex scopes, staffed by top-performing Web3 security researchers from Sherlock's network.

Products and services

  • Sherlock AI AI-powered smart contract analysis tool that delivers auditor-level analysis during development for Web3 protocol teams, using a two-stage run system (discovery plus verification), domain-specific specialist workflows, and GitHub integration to catch vulnerabilities early.
  • Collaborative Audits Private, senior-led code review engagements staffed from Sherlock's ranked researcher network. Sherlock assembles a curated expert team to review a protocol's codebase in a dedicated engagement with close developer collaboration, prior to mainnet or major releases.
  • Audit Contests Time-limited competitive security reviews that open a protocol's codebase to hundreds of independent researchers competing to surface the most impactful issues, applying large-scale adversarial pressure before protocol launch.
  • Bug Bounties Ongoing post-launch vulnerability discovery programs using a stake-to-submit model ($250 USDC per report, refunded if valid), with expert triage by Sherlock's lead auditors and a 52% hit rate on impactful submissions. Includes post-exploit coverage up to $500K for qualifying programs.
  • Sherlock Shield Financial exploit coverage product for live protocols that have been audited, adding a protection layer during active operation if a covered issue is exploited. Includes post-exploit coverage up to $500K for qualifying bug bounty programs.
  • Blackthorn Sherlock's elite audit tier, invite-only for top-performing researchers in the network and reserved for high-stakes infrastructure and complex scopes. Blackthorn researchers lead engagements on critical protocols such as Aave V4, Morpho Vaults V2, and the Ethereum Foundation Fusaka upgrade.

Quantifiable outcome

  • Supports protocols with $250B+ in active TVL
  • +4 more outcomes

Companies that use Sherlock

Customer profile

Named customers15 records

Segments1 record

Ideal customer profiles2 records

Sherlock technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Integration1 record

AI capability5 records

Feature9 records

Sherlock partnerships and signals

Strategic signal

Partnerships

Two partnerships are on record, tiered flagship.

  • UsualflagshipStrategic or Co-development Partner · 1 March 2026Usual partnered with Sherlock to launch the largest bug bounty in tech history at $16 million for a single critical vulnerability, eclipsing previous records by Uniswap ($15.5M) and LayerZero ($15M). The program covers Usual's full smart contract suite including stablecoin infrastructure, yield distribution, and governance contracts. Sherlock provides its stake-to-submit model with expert triage and post-exploit coverage.
  • Ethereum FoundationflagshipStrategic or Co-development Partner · 15 September 2025Ethereum Foundation's Protocol Security Team partnered with Sherlock for a large-scale audit contest as the final stress test before Fusaka's mainnet launch. The 28-day contest drew 510+ researchers with a $2M max prize pool. Sherlock mobilized its researcher network to surface 4 high-severity findings before the December 2025 Fusaka upgrade. The Foundation continues with an ongoing $250K bug bounty.

Scale indicators9 records

Recent moves6 records

Expansion highlights6 records

Sherlock competitors and assessment

Company assessment

Direct peers

  • Code4rena: Code4rena operates audit contests and bug bounties for Web3 protocols, directly competing with Sherlock's contest and bounty offerings. Both platforms use crowdsourced reviewer models to surface vulnerabilities before protocol launches.
  • Cantina: Cantina is a newer Web3 security platform offering audits, contests, and bug bounties with a curated researcher network. It competes directly with Sherlock across the audit contest and bug bounty product categories.
  • Spearbit: Spearbit provides curated smart contract audit services led by senior security researchers. It directly competes with Sherlock's Collaborative Audits and Blackthorn tier engagements.
  • Immunefi: Immunefi is the largest bug bounty platform specifically for Web3, directly competing with Sherlock's Bug Bounty product. Both platforms host ongoing vulnerability disclosure programs with major protocols.
  • Zellic: Zellic is a smart contract audit firm specializing in cryptographic and high-stakes protocol audits. It competes for premium audit engagements similar to Sherlock's Blackthorn tier.
  • Hacken: Hacken is a Web3 cybersecurity auditor offering smart contract audits, bug bounties, and security scoring services. It competes with Sherlock across multiple security service categories.

Broad incumbents

  • OpenZeppelin: OpenZeppelin is a leading smart contract security and development firm offering audits, security libraries, and developer tools. It is a broader incumbent with overlapping audit services but a different model (fixed roster of senior auditors rather than crowdsourced).
  • Trail of Bits: Trail of Bits is a well-established cybersecurity firm with significant Web3 smart contract audit practice. It competes for high-stakes audit engagements (e.g., Aave, Morpho) and offers broader security services beyond Web3.
  • Consensys Diligence: Consensys Diligence is the audit arm of Consensys, one of the largest Web3 infrastructure companies. It offers smart contract audits and competes for major protocol engagements as a broader incumbent.

Emerging players

  • Certora: Certora provides formal verification and security analysis tools for smart contracts. It is an emerging player using a different technical approach (formal verification) that overlaps with Sherlock AI's pre-launch analysis capabilities.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks5 records

Key highlights7 records

Customer concentration

Sherlock social profiles

Digital presence

Sherlock financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Sherlock leadership team

Management profile

Number of profiles

Profiles2 records

Sherlock funding detail

Funding detail

Funding overview

Funding rounds1 record

Investors5 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Sherlock M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Sherlock

What does Sherlock do?

Sherlock provides lifecycle security services for Web3 protocols, combining AI-powered smart contract analysis (Sherlock AI), senior-led private audits (Collaborative Audits, including the Blackthorn elite tier), large-scale adversarial contests (Audit Contests), ongoing post-launch vulnerability discovery (Bug Bounties), and financial exploit coverage (Sherlock Shield). Engagements are staffed from a network of 11,000+ ranked security researchers matched to each protocol's architecture.

Is Sherlock a public or private company?

Sherlock is a private company. It is classified as venture growth investor backed and is currently operating.

When was Sherlock founded?

Sherlock was founded in 2021. It employs 101 to 250 people.

Where is Sherlock based?

Sherlock is headquartered in Miami, United States, in the North America region.

How does Sherlock make money?

Five revenue lines are on record. Collaborative Audits are the primary driver. The others are audit Contests, bug Bounties, referral Program and sherlock Shield Coverage.

Who are Sherlock's main competitors?

Direct peers on record are Code4rena, Cantina, Spearbit, Immunefi, Zellic and Hacken. Broad incumbents are OpenZeppelin, Trail of Bits and Consensys Diligence. Certora is listed as an emerging player.

Does Sherlock have an API?

No public API is recorded for Sherlock.

What industry is Sherlock in?

Sherlock's product category is Web3 Smart Contract Security Services. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services, with a secondary code of FSAPAJAB, On-Chain Monitoring, Threat Detection & Incident Response. Its NAICS code is 561621 and its SIC code is 6200.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
AInvestAerodrome Finance Launches $400,000 Sherlock Audit Ahead of Aero UpgradeAerodrome Finance has launched a $400,000 public security audit contest on the Sherlock platform to validate its upcoming Aero upgrade before the scheduled September mainnet launch on Base. The upgrade introduces Predictive Allocation to align liquidity provider rewards with actual fee generation and finalizes the merger of Aerodrome and Velodrome into a unified liquidity layer. Previous private audits by ChainSecurity and Sherlock found no critical vulnerabilities, allowing this public phase to focus on identifying remaining issues.TechBullionSherlock Launches Audit Engine to Solve AI Security Tool SprawlWeb3 security company Sherlock launched the Audit Engine, a platform designed to coordinate multiple AI-powered security systems within a single environment. The tool consolidates findings from various models and auditors by handling validation, deduplication, and synthesis to address the operational challenges of managing expanding AI security toolsets.CoinMarketCapXRP Ledger 3.3.0 Goes Live, Paving the Way for Advanced DeFi and Tokenization Through Institutional-Ready Infrastructure: Guest Post by Coinpaper.comThe XRP Ledger Operations team has released xrpld version 3.3.0, one of the network's most significant upgrades to date, introducing infrastructure built for institutional finance, tokenization, privacy, and advanced decentralized applications. The upgrade includes six new amendments in validator voting, featuring Confidential Transfers for native privacy, Batch Transactions for atomic execution, Permission Delegation for enterprise wallet management, and the Sponsor amendment for third-party fee coverage. Security audits by Web3 firm Sherlock identified and resolved 2 critical, 6 high, 29 medium, and 59 low-severity vulnerabilities before release, with 309,000 RLUSD awarded through the bug bounty program.CoinMarketCapXRP Ledger 3.3.0 Moves Closer as Community Security Review Exposes 96 Valid Findings: Guest Post by 36cryptoThe XRP Ledger is advancing toward its 3.3.0 protocol upgrade following the completion of a community-driven security review of five proposed amendments covering privacy, transaction efficiency, and institutional capabilities. The two-week adversarial review, conducted by security firm Sherlock, uncovered 96 valid findings including 2 critical and 6 high-severity issues, with Ripple distributing $309,000 in RLUSD rewards to participants whose submissions identified vulnerabilities. Developers will now address the reported findings before the proposed amendments proceed through the network's validator consideration and activation process.U.TodayNew XRP Ledger Features Face Community Stress Test: Is Next XRPL Update Ready to Drop?Ripple has engaged Web3 security firm Sherlock to conduct adversarial testing on five upcoming features in the XRP Ledger version 3.3.0 upgrade, with community participants uncovering 2 Critical, 6 High, 29 Medium, and 59 Low severity issues and unlocking $309,000 in RLUSD rewards. The testing covered Confidential MPTs, Batch transactions, Permission Delegation, Sponsored Fees and Reserves, and Dynamic MPT functionality. The XRP community anticipates the release of version 3.3.0, which follows a hotfix (version 3.2.1) deployed on August 1 for a manifest flood issue.PanewslabDeFi 保险为什么没人买?DeFi insurance remains unattractive because premiums erode returns and risk pools are too small. Nexus Mutual, the largest provider, has paid only $18 million in claims over seven years, while a single Kelp DAO hack cost $292 million. The industry's underwriting capacity cannot cover trillions in locked assets.TechBullionSmart Contract Security Auditing Becomes a US Specialist ProfessionSmart contract security auditing has evolved from a hobbyist practice in 2016 to an enterprise-grade profession employing 30-120+ engineers per firm, driven by $1.6 billion in crypto exploits in 2025 and the 2016 DAO hack that drained $50 million. Major audit firms Trail of Bits, OpenZeppelin, ConsenSys Diligence, Quantstamp, and CertiK now operate alongside contest platforms Code4rena and Sherlock, with top-tier engagements charging approximately $25,000 per engineer-week. Emerging trends through 2027 include the development of standardized audit frameworks by the Crypto Council for Innovation, increasing OCC regulatory expectations for bank-adjacent contracts, and the integration of post-quantum cryptography standards (NIST FIPS 203, 204, 205) into deployed smart contract codebases.TechBullionIs Exolane Safe? Security Review, Risks, and On-Chain ArchitectureThis article provides a technical security review of Exolane, a decentralized leveraged perpetuals exchange operating on Arbitrum One, examining its on-chain architecture and risk design properties. The protocol holds user USDC collateral in smart contracts rather than custodial wallets, uses Pyth Network for oracle pricing with a 40-second staleness threshold, and has undergone seven security audit rounds by Sherlock and Zellic between August 2023 and February 2025. Key design features include a seven-day timelock for protocol upgrades, zero liquidation penalties, a hard funding rate cap of ±15% APR, and an oracle-settled execution model designed to reduce MEV and front-running vulnerabilities.openPR.comNext Crypto to Hit $1: OzoraAI ($OZO) Presale Gains Momentum as AI Trading Tools Go MainstreamOzoraAI is conducting a presale for its $OZO token on the Ethereum network at 0.0001 dollars per token with a long-term target of one dollar, having raised over fifty thousand dollars from the sale of more than fifty million tokens as of March 2026. The project offers AI-powered trading prediction tools and its smart contracts have been audited by security firms Certik and Sherlock. The article frames the presale as an investment opportunity for beginners seeking exposure to AI-driven cryptocurrency projects with potential for significant returns.openPR.comBest Crypto Presale 2026: OzoraAI ($OZO) Agentic AI Platform Rides Bitcoin ETF Inflows in MarchOzoraAI has launched the presale for its $OZO token, an agentic AI platform offering real-time predictive intelligence across crypto, equities, and forex markets, with the presale priced at $0.0001 per token and a long-term analyst target of $1. The article highlights that March 2026 has seen approximately $2 billion in Bitcoin ETF inflows, with BlackRock's iShares Bitcoin Trust driving significant institutional capital into the market. OzoraAI claims its smart contracts have been audited by Certik and Sherlock, and the presale has raised over $50,000 as of the latest data.